CVE-2026-20476: Medium severity ccci vulnerability
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For the ccci out-of-bounds read (missing bounds check) that can cause local denial of service with user execution privileges (Patch ID: ALPS10981532; Issue ID: MSV-7660), apply the vendor patch corresponding to ALPS10981532 to remediate the issue.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20476?
CVE-2026-20476 has a medium severity rating of 5.5 according to CVSS 3.1.
What is the risk associated with CVE-2026-20476?
The risk associated with CVE-2026-20476 is identified as a risk score of 32.
How do I fix CVE-2026-20476?
To fix CVE-2026-20476, apply the patch with ID ALPS10981532 as recommended.
What type of vulnerability is CVE-2026-20476?
CVE-2026-20476 is characterized as an out of bounds read vulnerability.
Is user interaction required to exploit CVE-2026-20476?
No, user interaction is not needed to exploit CVE-2026-20476.